Compare commits

..

19 Commits

Author SHA256 Message Date
heath effd8336cd renamed hpf 2026-07-24 14:36:34 -05:00
heath 246737d212 renamed .profile 2026-07-24 14:13:54 -05:00
heath aff550d586 renamed ansible-venv.sh 2026-07-24 14:05:46 -05:00
heath 716ac04c4f changed to just replace skeletion .profile 2026-07-24 13:56:54 -05:00
heath 438c4d2100 clean up bootstrap.sh 2026-07-24 13:07:37 -05:00
heath 36369f1ad6 x 2026-07-24 12:04:57 -05:00
heath f4f2b96d1a x 2026-07-24 12:00:43 -05:00
heath 9f1db4076f cleanup 2026-07-24 11:41:39 -05:00
heath da8db08d78 working on profile.d/ansible-venv.sh 2026-07-16 21:05:41 -05:00
heath f2661aaf02 comment out ansible pull until branches are implemented 2026-07-15 19:44:04 -05:00
heath 44766173bd back up files in bootstrap.sh 2026-07-15 19:32:54 -05:00
heath c5b8ada835 x 2026-07-15 18:54:57 -05:00
heath b25e844c0a x 2026-07-15 18:52:28 -05:00
heath dc490c1613 x 2026-07-15 18:49:30 -05:00
heath c2dcfa2996 cleanup 2026-07-15 18:27:10 -05:00
heath 16e3a9cbe2 shorten file names 2026-07-15 17:14:01 -05:00
heath 117821b738 clean house 2026-07-15 16:49:18 -05:00
heath 0e3f78b695 continue working on supporting multiple branches 2026-07-12 18:12:53 -05:00
heath ba750bed89 start supporting multiple branches 2026-07-12 17:39:57 -05:00
10 changed files with 428 additions and 35 deletions
+79 -28
View File
@@ -1,4 +1,4 @@
#!/bin/sh
#!/usr/bin/env sh
####
#### WARNING:
@@ -22,19 +22,27 @@
#### VARIABLES
#
TIMESTAMP="$(date "+%Y%m%d%H%M%S")"
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
GIT_REPO="${GIT_REPO_BASE}.git"
GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/files/etc_sudoers_d_hpf"
GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/files/home_hpf_ans_bin_ansible_pull_sh"
GIT_REPO_BRANCH="${1:-"development"}"
GIT_REPO_FILES="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files"
ETC_sudoers_d_hpf="/etc/sudoers.d/hpf"
GIT_REPO_sudoers_d_hpf="${GIT_REPO_FILES}/etc/sudoers.d/hpf"
GIT_REPO_SKEL_ansible_venv_sh="${GIT_REPO_FILES}/etc/skel/.profile.d/ansible-venv.sh"
GIT_REPO_SKEL_profile="${GIT_REPO_FILES}/files/etc/skel/.profile"
GIT_REPO_ansible_pull_sh="${GIT_REPO_FILES}/ansible_pull_sh"
HPF_ANS_ansible_venv="\${HOME}/.ansible-venv"
HPF_ANS_activate="${HPF_ANS_ansible_venv}/bin/activate"
ETC_sudoers_d="/etc/sudoers.d"
ETC_sudoers_d_hpf="${ETC_sudoers_d}/hpf"
HPF_ANS_bin="\${HOME}/bin"
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
unset SKEL
if [ -r /etc/default/useradd ] ; then . /etc/default/useradd ; fi
SKEL="${SKEL:-/etc/skel}"
SKEL_profile_d="${SKEL}/.profile.d"
SKEL_ansible_venv_sh="${SKEL_profile_d}/ansible-venv.sh"
SKEL_profile="${SKEL}/.profile"
ANSIBLE_PULL_SH_LOG_DIR="/var/log/ansible-pull.sh"
@@ -86,9 +94,41 @@ add_groups_to_user () {
fi
}
# $source_file $dest_file $dest_file_ownership $dest_file_permissions
get_file() {
local source_file dest_file dest_file_ownership dest_file_permissions
source_file="${1}"
dest_file="${2}"
dest_file_ownership="${3}"
dest_file_permissions="${4}"
if [ -e "${dest_file}" ] ; then mv "${dest_file}" "${dest_file}.${TIMESTAMP}" ; fi
if ! curl -f -o "${dest_file}" "${source_file}" ; then
echo "ERROR - Unable to download \"${source_file}\"" >&2
echo " to \"${dest_file}\"." >&2
exit 4
fi
chown "${dest_file_ownership}" "${dest_file}"
chmod "${dest_file_permissions}" "${dest_file}"
}
# $directory $directory_ownership $directory_permissions
create_directory() {
local directory directory_ownership directory_permissions
directory="${1}"
directory_ownership ="${2}"
directory_permissions="${3}"
mkdir -p "${directory}"
chown "${directory_ownership}" "${directory}"
chmod "${directory_permissions}" "${directory}"
}
# $command_line
as_hpf_ans () {
su --login hpf-ans -c "if [ -r \"${HPF_ANS_activate}\" ] ; then source \"${HPF_ANS_activate}\" ; fi ; ${1}"
su --login hpf-ans --command "${1}"
}
@@ -97,8 +137,8 @@ as_hpf_ans () {
#
# Make sure we're running as root
if [ $(id -u) -ne 0 ] ; then
echo "ERROR - Not running as root!" >&2
if [ "$(id -u)" -ne 0 ] ; then
echo "ERROR - Not running as root" >&2
exit 100
fi
@@ -117,17 +157,32 @@ system_groupadd hpf-sudo 700
# Create system group hpf-sudo-np for special sudo users that don't require a password
system_groupadd hpf-sudo-np 701
# Create /etc/sudoers.d/hpf to allow common sudo permissions
rm "${ETC_sudoers_d_hpf}" 2>/dev/null
curl -o "$ETC_sudoers_d_hpf" "${GIT_REPO_sudoers_d_hpf}"
chown root:root "${ETC_sudoers_d_hpf}"
chmod u=rw,go= "${ETC_sudoers_d_hpf}"
# Make sure /etc/sudoers.d exists
create_directory "${ETC_sudoers_d}" "root:root" "u=rwx,go="
# Get /etc/sudoers.d/hpf
get_file "${GIT_REPO_sudoers_d_hpf}" "${ETC_sudoers_d_hpf}" "root:root" "u=rw,go="
# Make sure /etc/skel/.profile.d exists
create_directory "${SKEL_profile_d}" "root:root" "u=rwx,go="
# Get /etc/skel/.profile.d/ansible-venv.sh
get_file "${GIT_REPO_SKEL_ansible_venv_sh}" "${SKEL_ansible_venv_sh}" "root:root" "u=rwx,go="
# Get /etc/skel/.profile
get_file "${GIT_REPO_SKEL_profile}" "${SKEL_profile}" "root:root" "u=rw,go=r"
# Create the hpf-ans user
system_useradd hpf-ans 800
add_groups_to_user hpf-sudo-np hpf-ans
# Make sure .ansible-venv exists
# Set HPF_ANS variables now that the user is created
HPF_ANS_HOME="$(as_hpf_ans 'echo "${HOME}"')"
HPF_ANS_ansible_venv="${HPF_ANS_HOME}/.ansible-venv"
HPF_ANS_bin="${HPF_ANS_HOME}/bin"
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
# Make sure /home/hpf-ans/.ansible-venv exists
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi"
# Make sure pip is up to date
@@ -136,18 +191,14 @@ as_hpf_ans "pip install --upgrade pip"
# Make sure ansible is installed
as_hpf_ans "pip install --upgrade ansible"
# Make sure bin exists
as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\""
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\""
# Make sure /home/hpf-ans/bin exists
create_directory "${HPF_ANS_bin}" "hpf-ans:hpf-ans" "u=rwx,go="
# Create ~hpf-ans/bin/ansible-pull.sh
as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null"
as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\""
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\""
# Get /home/hpf-ans/bin/ansible-pull.sh
get_file "${GIT_REPO_ansible_pull_sh}" "${HPF_ANS_ansible_pull_sh}" "hpf-ans:hpf-ans" "u=rwx,go="
# Make sure log directory exists
mkdir -p "${ANSIBLE_PULL_SH_LOG_DIR}"
chown hpf-ans:root "${ANSIBLE_PULL_SH_LOG_DIR}"; chmod ug=rwx,o= "${ANSIBLE_PULL_SH_LOG_DIR}"
create_directory "${ANSIBLE_PULL_SH_LOG_DIR}" "hpf-ans:root" "u=rwx,go="
# Run ansible-pull to finish up
as_hpf_ans "bin/ansible-pull.sh bootstrap.yml"
#as_hpf_ans "$HPF_ANS_ansible_pull_sh --branch ${GIT_REPO_BRANCH} bootstrap.yml"
+36 -5
View File
@@ -23,12 +23,12 @@
- name: bootstrap
hosts: all
become: yes
tasks:
- name: Install bootstrap packages
ansible.builtin.apt:
become: yes
state: latest
pkg:
- bash
@@ -40,6 +40,7 @@
- name: Make sure hpf-sudo group exists
ansible.builtin.group:
become: yes
name: hpf-sudo
state: present
system: true
@@ -47,6 +48,7 @@
- name: Make sure hpf-sudo-np group exists
ansible.builtin.group:
become: yes
name: hpf-sudo-np
state: present
system: true
@@ -54,6 +56,7 @@
- name: Copy over /etc/sudoers.d/hpf
ansible.builtin.copy:
become: yes
src: etc_sudoers_d_hpf
dest: /etc/sudoers.d/hpf
owner: root
@@ -62,8 +65,38 @@
backup: true
validate: /usr/sbin/visudo -csf %s
#### .profile.d should be in SKEL directory - look it up
- name: Make sure .profile.d directory exists
ansible.builtin.file:
become: true
path: /etc/skel/.profile.d
state: directory
owner: root
group: root
mode: u=rwx,go=
#### ansible-venv.sh should be in SKEL directory - look it up
- name: Copy over ansible-venv.sh
ansible.builtin.copy:
become: true
src: profile_d_ansible_venv_sh
dest: /etc/skel/.profile.d/ansible-pull.sh
owner: root
group: root
mode: u=rwx,go=
backup: true
#### .profile
- name: Make sure hpf-ans group exists
ansible.builtin.group:
become: yes
name: hpf-ans
state: present
system: true
@@ -71,6 +104,7 @@
- name: Make sure hpf-ans user exists
ansible.builtin.user:
become: yes
name: hpf-ans
state: present
system: true
@@ -86,14 +120,12 @@
name: pip
virtualenv: $HOME/.ansible-venv
extra_args: --upgrade
become: no
- name: Install latest version of ansible in .ansible-venv
ansible.builtin.pip:
name: ansible
virtualenv: $HOME/.ansible-venv
extra_args: "--upgrade"
become: no
- name: Make sure bin directory exists
ansible.builtin.file:
@@ -102,7 +134,6 @@
owner: hpf-ans
group: hpf-ans
mode: u=rwx,go=
become: no
- name: Copy over bin/ansible-pull.sh
ansible.builtin.copy:
@@ -112,10 +143,10 @@
group: hpf-ans
mode: u=rwx,go=
backup: true
become: no
- name: Make sure log directory exists
ansible.builtin.file:
become: yes
path: /var/log/ansible-pull.sh
state: directory
owner: hpf-ans
+34
View File
@@ -0,0 +1,34 @@
# ~/.profile: executed by the command interpreter for login shells.
# This file is not read by bash(1), if ~/.bash_profile or ~/.bash_login
# exists.
# see /usr/share/doc/bash/examples/startup-files for examples.
# the files are located in the bash-doc package.
# the default umask is set in /etc/profile; for setting the umask
# for ssh logins, install and configure the libpam-umask package.
#umask 022
# if running bash
if [ -n "$BASH_VERSION" ]; then
# include .bashrc if it exists
if [ -f "$HOME/.bashrc" ]; then
. "$HOME/.bashrc"
fi
fi
# set PATH so it includes user's private bin if it exists
if [ -d "$HOME/bin" ] ; then
PATH="$HOME/bin:$PATH"
fi
# set PATH so it includes user's private bin if it exists
if [ -d "$HOME/.local/bin" ] ; then
PATH="$HOME/.local/bin:$PATH"
fi
if [ -d "$HOME/.profile.d" ] ; then
for profile_script in $HOME/.profile.d/*.sh ; do
. "${profile_script}"
done
fi
@@ -0,0 +1,6 @@
ANSIBLE_ACTIVATE="${HOME}/.ansible-venv/bin/activate"
if [ -r "${ANSIBLE_ACTIVATE}" ] ; then
VIRTUAL_ENV_DISABLE_PROMPT=true
. "${ANSIBLE_ACTIVATE}"
fi
@@ -1,7 +1,23 @@
#!/bin/bash
# - Fix branch to check out
# - Process command line
GIT_REPO_BRANCH="production"
while [ $# -gt 0 ]; do
case "$1" in
-h|--help)
echo "Usage: $0 [--branch <branch name>]"
exit 0
;;
--branch)
shift 1
if [ $# -eq 0 ] ; then echo "$0: ERROR - Branch not specified." ; exit 1 ; fi
GIT_REPO_BRANCH="$1"
shift 1
;;
esac
done
# - Include ansible virtual environment
. "${HOME}/.ansible-venv/bin/activate"
SCRIPT_NAME="$(basename "${0}")"
@@ -23,5 +39,5 @@ if ! flock -n 9 ; then echo " - ERROR - Another copy of ${SCRIPT_NAME} is alread
# - Do our work
echo
ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout main "${@}"
ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}"
+35
View File
@@ -0,0 +1,35 @@
#!/usr/bin/env sh
if [ -z "${1:-}" ] ; then
echo "ERROR - ansible OS family unspecified." >&2
exit 1
fi
ANSIBLE_OS_FAMILY="${1}"
shift
useradd_D() {
case "${ANSIBLE_OS_FAMILY}" in
Debian)
/usr/sbin/useradd -D
;;
RedHat)
/usr/sbin/useradd -D
;;
*)
echo "ERROR - Unknown ansible OS FAMILY \"${ANSIBLE_OS_FAMILY}\"." >&2
exit 99
;;
esac
}
user_vars() {
useradd_D | sed 's/.*=/hpf_fact_\L&/'
}
#echo '{"hpf":'
#(user_vars; ) | jo
#echo '}'
user_vars
+116
View File
@@ -0,0 +1,116 @@
* create production, development branches
* have bootstrap.sh get ansible_pull_branch variable value
* have bootstrap.yml use ansible.builtin.blockinfile to maintain /etc/skel/.profile
# add /home/hpf-ans/bin/ansible-pull.sh crontab
* Configure hosts
# cat >>/etc/hosts <<!!TheEnd!!
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
!!TheEnd!!
* Configure chrony
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
pool 0.north-america.pool.ntp.org iburst
!!TheEnd!!
* Configure SSH
# cat >/etc/ssh/sshd_config.d/hpetersenfamily.conf <<!!TheEnd!!
PasswordAuthentication no
PermitEmptyPasswords no
PermitRootLogin no
!!TheEnd!!
# cat >>/home/first/.ssh/authorized_keys <<!!TheEnd!!
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBM5BBUOxkuSK7WlpaDvp6lrM9ajLSyh4PWD7VFzYOFN5/zfafy6Vf/oxtLE4UACw5ZGvBMQNH40bW+T9aO0lQ9g= first Heath@HPetersenFamily.com
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBBFiio/AimTUloJdfk4TXyWO7A0Fd9SoUcqheBjEvj4TnrxpSL/EhwF2CU9jZTasm6NBo2eKcH4aMt1l2ejOtIM= heath Heath@HPetersenFamily.com
!!TheEnd!!
##########
########## normal tasks
##########
- name: Install openssh, openssh-server, openssh-sftp-server
ansible.builtin.apt:
pkg:
- openssh
- openssh-server
- openssh-sftp-server
- name: Install bash, bash-completion
ansible.builtin.apt:
pkg:
- bash
- bash-completion
- name: Install chrony
ansible.builtin.apt:
pkg:
- chrony
#- name: Set host name
# ansible.builtin.hostname:
# name: ## Fully qualified domain name ##
# use: systemd
- name: Copy a new sudoers file into place, after passing validation with visudo
ansible.builtin.template:
src: /mine/sudoers
dest: /etc/sudoers
validate: /usr/sbin/visudo -cf %s
- name: Update sshd configuration safely, avoid locking yourself out
ansible.builtin.template:
src: etc/ssh/sshd_config.j2
dest: /etc/ssh/sshd_config
owner: root
group: root
mode: '0600'
validate: /usr/sbin/sshd -t -f %s
backup: yes
proxmox-clients
hw:
pve-lxc:
pve-oci:
pve-kvm:
users: first, heath, hpf-ans
~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
~heath/.ssh/authorized_keys
~first/.ssh/authorized_keys
~heath/.gitconfig
fail2ban
uptime kuma
==============================================================
==============================================================
==============================================================
logrotate /var/log/ansible-pull.log
cron job for ansible-pull
use tags to do things like allow selecting software updates, software cleanup, etc.
ansible_os_family variable
ansible galaxy
have upgrade pip and ansible in ~hpf-ans/.ansible-venv
hashicorp vault
have ansible-pull.sh make sure only one copy is running
+34
View File
@@ -0,0 +1,34 @@
---
- name: test-get_hpf_facts.yml
hosts: all
tasks:
- name: Copy over get_hpf_facts.sh
ansible.builtin.copy:
src: hpf-ans/bin/get_hpf_facts.sh
dest: bin/get_hpf_facts.sh
owner: hpf-ans
group: hpf-ans
mode: u=rwx,go=gx
backup: true
- name: Run get_hpf_facts.sh
ansible.builtin.command:
cmd: bin/get_hpf_facts.sh {{ ansible_facts["os_family"] }}
register: hpf_facts
changed_when: false
- name: Convert k=v stdout into facts
ansible.builtin.set_fact:
"{{ item.split('=', 1)[0] }}": "{{ item.split('=', 1)[1] }}"
loop: "{{ hpf_facts.stdout.splitlines() }}"
- name: Print all variables
ansible.builtin.debug:
var: hostvars[inventory_hostname]
- name: Print skel
ansible.builtin.debug:
var: hpf_fact_skel
+70
View File
@@ -0,0 +1,70 @@
---
- name: test-get_useradd_settings.sh
hosts: all
tasks:
- name: Copy over bin/get_useradd_settings.sh
ansible.builtin.copy:
src: hpf-ans/bin/get_useradd_settings.sh
dest: bin/get_useradd_settings.sh
owner: hpf-ans
group: hpf-ans
mode: u=rwx,go=gx
backup: true
- name: Run get_useradd_settings.sh
ansible.builtin.command:
cmd: bin/get_useradd_settings.sh {{ ansible_facts["os_family"] }}
register: useradd_settings
changed_when: false
- name: Convert k=v stdout into variables
ansible.builtin.set_fact:
# great_heath:
# - "{{ item.split('=', 1)[0] }}": "{{ item.split('=', 1)[1] }}"
"HPF_{{ item.split('=', 1)[0] }}": "{{ item.split('=', 1)[1] }}"
# "{{ item.split('=', 1)[0] | trim }}": "{{ item.split('=', 1)[1] | trim }}"
loop: "{{ useradd_settings.stdout.splitlines() }}"
# - name: Convert key-value strings into variables
# vars:
# my_var: "SKEL= SKEL2=/etc/skel\nHEATH=great"
# ansible.builtin.set_fact: "{{ my_var }}"
# ansible.builtin.set_fact: "{{ useradd_settings.stdout }}"
# ansible.builtin.set_fact: "SKEL= SKEL2=/etc/skel\nHEATH=great"
# ansible.builtin.set_fact: "{{ useradd_settings.stdout | from_yaml }}"
# ansible.builtin.set_fact: "{{ useradd_settings.stdout }}"
# ansible.builtin.set_fact: "SKEL2=/etc/skel\nHEATH=great"
# - name: Convert key-value strings into variables
# ansible.builtin.set_fact:
# kv_vars: "{{ useradd_settings.stdout }}"
# - name: Print ansible variables
# ansible.builtin.debug:
# var: vars
# - name: Print SKEL
# ansible.builtin.debug:
# var: SKEL
# - name: Print heath.SKEL
# ansible.builtin.debug:
# var: heath.SKEL
# - name: Print SKEL2
# ansible.builtin.debug:
# var: SKEL2
# - name: Print HEATH
# ansible.builtin.debug:
# var: HEATH
- name: Print all variables
ansible.builtin.debug:
var: vars